US11736503B2ActiveUtilityA1

Detection of anomalous lateral movement in a computer network

Assignee: SALESFORCE COM INCPriority: Oct 22, 2019Filed: Sep 4, 2020Granted: Aug 22, 2023
Est. expiryOct 22, 2039(~13.2 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 63/0272H04L 63/168
84
PatentIndex Score
2
Cited by
9
References
20
Claims

Abstract

Various embodiments of methods for detecting anomalous activity in a computer network are disclosed. A method includes a computer system receiving an indication of a current session establishing a secure channel to a computing device within a network. The computer system evaluates information relating to the current session, as well as information relating to one or more other sessions. Using this information, the computing system performs monitoring to detect the presence of anomalous lateral movement within the network, for example based on detecting multiple user credentials. Based on the evaluating performed, the computer system generates a score for the current session and reports whether the score is indicative of anomalous lateral movement.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A method comprising:
 receiving, at a computer system, session information relating to a current session and one or more previous sessions in which a network is accessed by a particular user; 
 evaluating, by the computer system, network activity, wherein the evaluating includes:
 a first evaluation of a point of an entry into the network for the current session, wherein the point of entry is a host within the network at which the current session originated, wherein the first evaluation includes generating a prevalence value for the point of entry that is determined by aggregating user activity from different users based on a number and quality of links to the point of entry, and wherein the first evaluation further includes comparing the prevalence value to a threshold; and 
 a second evaluation of timing of the current session relative to previous session timing for the particular user, wherein the second evaluation includes determining whether timing information for the current session deviates from timing information for prior sessions of the particular user by comparing previous session times of the particular user with session times of the current session, wherein the previous session times include respective start times and durations of the prior sessions; and 
 
 determining, by the computer system, whether a score based on the evaluating is indicative of whether anomalous lateral movement is present within the network. 
 
     
     
       2. The method of  claim 1 , wherein the second evaluation is based on a user profile created using history data in secure shell session (SSH) logs for the particular user. 
     
     
       3. The method of  claim 1 , wherein the second evaluation is performed by applying principal component analysis on data in a user profile in order to determine timing anomalies for login activities of the particular user. 
     
     
       4. The method of  claim 1 , wherein the evaluating includes:
 a further evaluation of whether the particular user has an active Wi-Fi or virtual private network (VPN) connection to the network. 
 
     
     
       5. The method of  claim 1 , wherein the evaluating includes:
 a further evaluation of whether network activity associated with the particular user is anomalous relative to network activity of other users designated as peers to the particular user. 
 
     
     
       6. The method of  claim 5 , wherein the other users are designated as peers to the particular user based on a common job function. 
     
     
       7. The method of  claim 5 , wherein the other users are designated as peers to the particular user based on historical data. 
     
     
       8. The method of  claim 1 , wherein the evaluating includes:
 a third evaluation of whether the particular user has an active Wi-Fi or virtual private network (VPN) connection to the network; and 
 a fourth evaluation of whether network activity associated with the particular user is anomalous relative to network activity of other users designated as peers to the particular user. 
 
     
     
       9. A non-transitory, computer-readable medium having program instructions stored thereon that are capable of causing a computing system to implement operations comprising:
 determining that a particular user has a current session active with a computing device of a network; 
 evaluating information to detect anomalous lateral movement within the network, wherein the information relates to the current session and one or more additional sessions within the network, and wherein the evaluating includes:
 assessing a point of entry for the current session, wherein the point of entry is a host within the network at which the current session originated, using an algorithm that determines a prevalence of the point of entry relative to other computer systems in the network, wherein determining the prevalence includes assessing paths through the network for each of a plurality of users active during a particular time period, aggregating user path information to generate a prevalence score for the point of entry, and comparing the prevalence score to a threshold value; 
 assessing, using history information for the particular user, whether timing information for the current session deviates from timing information for prior sessions of the particular user by comparing previous session times of the particular user with session times of the current session, wherein the previous session times include respective start times and durations of the prior sessions; and 
 
 determining whether the evaluating is indicative of anomalous lateral movement within the network. 
 
     
     
       10. The computer-readable medium of  claim 9 , wherein the history information is based on secure shell (SSH) session logs for the particular user. 
     
     
       11. The computer-readable medium of  claim 9 , wherein assessing timing of the current session includes performing a principal component analysis algorithm on the history information for the particular user. 
     
     
       12. The computer-readable medium of  claim 9 , wherein the evaluating further includes assessing behavior of the particular user during the current session. 
     
     
       13. The computer-readable medium of  claim 9 , wherein the evaluating further includes assessing whether the particular user has an active WiFi or VPN connection to the network. 
     
     
       14. The computer-readable medium of  claim 9 , wherein the evaluating further includes assessing whether network activity of the particular user is anomalous relative to network activity of peers of the particular user. 
     
     
       15. A method, comprising:
 receiving, at a computer system, session information relating to a current session and one or more previous sessions in which a network is accessed; 
 evaluating, by the computer system, network activity that includes network activity associated with a particular user, wherein the evaluating includes determining a score based on: 
 a first sub-model that ranks a point of entry for the particular user relative to other network computer systems by generating a prevalence value for the point of entry using user graphs and a population graph that aggregates user activity in the network, wherein the point of entry is a host within the network at which the current session originated; and 
 a second sub-model that determines whether timing information of the current session deviates from timing information of prior sessions for the particular user by comparing previous session times of the particular user with session times of the current session, wherein the previous session times include respective start times and durations of the prior sessions; and 
 determining, by the computer system based on the score, whether anomalous lateral movement is present within the network. 
 
     
     
       16. The method of  claim 15 , wherein the evaluating further includes using a third sub-model that determines whether permissible network connection types are currently active. 
     
     
       17. The method of  claim 16 , wherein the permissible network connection types include WiFi and VPN. 
     
     
       18. The method of  claim 17 , wherein the permissible network connection types are WiFi connection, VPN connection, and wired connection. 
     
     
       19. The method of  claim 15 , wherein the second sub-model uses history information from secure shell (SSH) logs. 
     
     
       20. The method of  claim 15 , wherein the evaluating further includes using a fourth sub-model that detects anomalous activity during the current session relative to peers of the particular user.

Join the waitlist — get patent alerts

Track US11736503B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.